Chapter 13 Flashcards
what is a type 1 authentication factor?
something you know
what is a type 2 authentication factor?
something you have - CAC
what is a type 3 authentication factor?
something you are
What does NIST recommend regarding password expiration dates?
NIST does not recommend password expiration policies.
What does NIST recommend regarding special characters?
NIST does not recommend requiring special characters in passwords.
NIST password length recommendations
between 8 and 64 characters
What does PCI DSS recommend for password expiration?
Passwords should expire every 90 days
PCI DSS password length minimum
7 characters
tokens that are time based and generate a new PIN periodically
synchronous dynamic password tokens
tokens that are generated based on an algorithm and an incrementing counter which increases each time the user authenticates
asynchronous dynamic password tokens
Type I error is also known as the False ____ Rate
Rejection
Type II error is also known as the False ___ Rate
Acceptance
Is Type I or Type II error more dangerous regarding security?
Type II because it can grant access to an unauthorized user
should a device operate at the CER level?
No, you want the sensitivity higher than the CER rate to decrease the number of Type II errors
the amount of time required to scan a biometric factor
enrollment time